Files
mandiant-capa-rules/communication/send-data.yml
T
2020-09-29 15:05:11 -04:00

17 lines
474 B
YAML

rule:
meta:
name: send data
namespace: communication
author: william.ballenthin@fireeye.com
description: all known techniques for sending data to a potential C2 server
scope: function
mbc:
- Command and Control::C2 Communication::Send Data [B0030.001]
examples:
- BFB9B5391A13D0AFD787E87AB90F14F5:0x13145D60
features:
- or:
- match: send HTTP request
- match: send data on socket
- match: send file via HTTP